A vulnerability in MEPSAN's USC+ before version 3.0 has a weakness in login function which lets attackers to generate high privileged accounts passwords.
Solution:
The authentication algorithm is sound, but the implemented mechanism can be bypassed as the result of a separate weakness that is primary to the authentication error.
Link | Tags |
---|---|
https://www.usom.gov.tr/bildirim/tr-22-0269 | third party advisory |